A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code or to cause a denial of service condition.
The vulnerability, classified as CWE-121 (Stack-based Buffer Overflow), occurs in the integrated UMC component embedded in SIMATIC PCS neo products. An attacker can send specially crafted network data to the vulnerable component without requiring any credentials. The stack buffer overflow can lead to overwriting critical program control flow structures, enabling arbitrary code execution (RCE) or destabilizing the running process (DoS).
A remote, unauthenticated attacker can execute arbitrary code on the vulnerable system or cause its unavailability by triggering a denial of service. In the context of industrial process control systems (DCS), the impact may include disruption of production process continuity.
SIMATIC PCS neo V6.0 should be updated to version V6.0 SP1 Update 1 or later, and User Management Component (UMC) to version V2.15.1.3 or later. For versions V4.1 and V5.0, which are vulnerable in all versions, follow the recommendations from Siemens available at https://cert-portal.siemens.com/productcert/html/ssa-722410.html. It is also recommended to restrict network access to vulnerable UMC components at the firewall level and isolate control systems from external networks.
SIMATIC PCS neo V4.1 (all versions), SIMATIC PCS neo V5.0 (all versions), SIMATIC PCS neo V6.0 (all versions below V6.0 SP1 Update 1), User Management Component (UMC) (all versions below V2.15.1.3)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Simatic Pcs Neo
APPSiemens4.15.0Siemens User Management Component
APPSiemens< 2.15.1.3
Related vulnerabilities
Buffer over-read w Wibu-Systems CodeMeter — ujawnienie pamięci lub crash
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (A...
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions...
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions...
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions...